crewai

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
references/11-mcp-integration.md

No direct, explicit malware logic (e.g., backdoor, eval-based payload, or obvious exfiltration) is shown in the provided fragment. The primary security concern is architectural: it demonstrates launching MCP servers via `npx`/`python` (runtime code execution with supply-chain exposure) and passes secret-like credentials into the spawned MCP process environment, while agent-controlled inputs can drive database/search or ticket-creation operations. Without version pinning/integrity controls, secret redaction, and a reviewed/isolated MCP server implementation, the security risk remains elevated.

Confidence: 52%Severity: 60%
Audit Metadata
Analyzed At
Sep 4, 2026, 10:32 AM
Package URL
pkg:socket/skills-sh/abhisheksharma-17%2Fskills-graph%2Fcrewai%2F@7aab55e97e62b88f3ff9b931553ca5c212249637c7b23c373137a2178a02b27a
Security Audit — socket — crewai